Forums: The Feds Can Own Your Wlan Too - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

The Feds Can Own Your Wlan Too FBI Demostrate WEP Cracking

#1 User is offline   myth 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 09-January 04

Posted 06 April 2005 - 01:25 AM

http://www.tomsnetwo...le111-page1.php

In a recent ISSA (Information Systems Security Association) in Los Angeles, a team of FBI agents were showing the awaiting crowd exactly how easy it is to crack WEP encryption.

They used most of the tools we've all used and tried before, but its always good to read an article from different sources, and this is probably my first 'how-to-hack' article from the FBI...

They used the obvious tools:

Quote

    * Kismet
    * Airsnort
    * Aircrack (includes Aireplay and Airodump)
    * void11


except I found a new security distro, NOT BASED ON KNOPPIX ! Well, atleast not the current version, still downloading atm, but i hope this distro maybe another to add to my collection, indead of having most of them all based on Knoppix...

* Auditor's Security Collection - Contains all the wireless hacking tools already installed

http://new.remote-ex...x.php/Main_Page <- can be found there
0

#2 User is offline   r00t 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 85
  • Joined: 17-June 03

Posted 06 April 2005 - 03:45 AM

Myth1368

Kewl story. I will test my own network now. An look if im secure enough :D
0

#3 User is offline   shirkdog 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 34
  • Joined: 21-October 04

Posted 06 April 2005 - 06:12 AM

nebo, on Apr 6 2005, 07:45 AM, said:

Hi Myth1368

Very intresting Post. I've wanted to test my own w - lan network but my w -lan network card isn't compatible with the tools. It haven't the special chip you need.


But thx anyway.


Auditor is one of the best bootable security distros for wireless hacking. It is regularly updated and a NEW version was released a couple of weeks ago.
0

#4 User is offline   Dennis 

  • Specialist
  • Icon
  • Group: Specialist
  • Posts: 2,528
  • Joined: 08-September 04

Posted 08 April 2005 - 12:05 AM

I think the new whoppix does a fine job too...


FLX
Read the rules to prevent yourself from getting banned

"Battle not with monsters, lest ye become a monster. And if thou gaze long into the abyss, the abyss will also gaze into thee.
"
- Friedrich Wilhelm Nietzsche

0

#5 User is offline   Xcaliber 

  • Private First Class
  • Icon
  • Group: GOVNET
  • Posts: 31
  • Joined: 20-September 03

Posted 08 April 2005 - 06:53 AM

Myth1368, on Apr 6 2005, 03:25 AM, said:

http://www.tomsnetwo...le111-page1.php

In a recent ISSA (Information Systems Security Association) in Los Angeles, a team of FBI agents were showing the awaiting crowd exactly how easy it is to crack WEP encryption.


http://new.remote-ex...x.php/Main_Page <- can be found there


Doesn't really surprise me that the FBI would demonstrate this--after all, they have the best encryption-crackers in the world (as far as I know); I have never seen software (we're not talking about the ones freely available or well known), nor their special agent brain childs (their intelligence scares me), work the way they do. For them, and for all of us in this post that are capable of doing it, cracking WEP is a cake walk.

What does surprise me is a public display, even if it is an easy task for them.
0

#6 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 09 April 2005 - 06:24 AM

Maybe everyone should change to WPA, or to another encryption algorithm, because even FBI writes a tutorial about WEP Cracking...
BTW, there's a good Auditor tutorial, here, in this forum. Search for it if you are interested... And as another security collection, I heard of WarLinux.
And I sometimes think whether we should remain on WPA after reading the WPA cracking tutorial... (it's here in the forum, too)
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#7 User is offline   tibbar 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,423
  • Joined: 14-October 03

Posted 09 April 2005 - 10:22 PM

to be honest i find the wep weakness very annoying.

i purchased a hardware wireless router a while back, and the firmware hasnt been upgraded for wpa.

but i run a home network with many file shares etc between boxes and now any wardriver can hack in after 5 mins from a car outside.

even securing the net to my own mac addresses wont stop the determined, as you can just reconfigure your wireless card to a spoof mac addy.

guess i will have to install old fashioned cable in my house!
If you want to read more about my security research, visit Tibbar.org
0

#8 User is offline   d4s!d 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 46
  • Joined: 08-September 03

Posted 09 May 2005 - 08:25 PM

Warlinux is old already...
an other good dis for wireless audits can you find here

a list with the tools included can you find here

hf
0

#9 User is offline   sabrodiesel2000 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 157
  • Joined: 30-April 05

Posted 15 May 2005 - 08:42 AM

tibbar, on Apr 10 2005, 06:22 AM, said:

to be honest i find the wep weakness very annoying.

i purchased a hardware wireless router a while back, and the firmware hasnt been upgraded for wpa.

but i run a home network with many file shares etc between boxes and now any wardriver can hack in after 5 mins from a car outside.

even securing the net to my own mac addresses wont stop the determined, as you can just reconfigure your wireless card to a spoof mac addy.

guess i will have to install old fashioned cable in my house!



u could always try Netstumbler, it helps u view all the connected access point in ur wireless network!
0

#10 User is offline   myth 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 09-January 04

Posted 15 May 2005 - 08:50 PM

I dont have time to make a thread about this atm, but i will soonish...

Remove WEP and WPA if your running it...

Well, check if you have the function for a VPN Server first :P

People are able to connect to my wireless network. Hell, i'd invite them too. But thats it. My VPN wont allow them to do squat, and allows encryption and authentication...

Atm, im working on another plan for war drivers, ie when they connect, do a port scan etc and monitor them (because they dont have a registerd MAC addy etc)

Still a work in progress, but i'll get around to sharing it sooner than later
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting